Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wiggly Wayne DDS
Sep 11, 2010



earlier today 3 key recovery attacks on aes-gcm-siv were unveiled on cfrg (1st is important): https://mailarchive.ietf.org/arch/msg/cfrg/k2mpWgod4mbdOxsvN6EtXHb0BAg

more eyepyramid info, it uses a lot more third-party software than previously thought: https://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-inner-workings-eyepyramid/

ongoing fun with manufacturer test accounts, awaiting part 2: https://research.trust.salesforce.com/Meraki-RCE-When-Red-Team-and-Vulnerability-Research-fell-in-love.-Part-1/

Adbot
ADBOT LOVES YOU

30 TO 50 FERAL HOG
Mar 2, 2005



eBay still lets you embed flash content into your listings apparently, so how about some auto downloading malware that makes it look like the official apple website



http://www.ebay.com/itm/350983607686?_trksid=p2060353.m2749.l2649&ssPageName=STRK%3AMEBIDX%3AIT

yoloer420
May 19, 2006

hackbunny posted:

Blahblah dotnet blah

DnSpy

MononcQc
May 29, 2007

fisting by many posted:

krebs released his big expose on the mirai author

https://krebsonsecurity.com/2017/01/who-is-anna-senpai-the-mirai-worm-author/

it's minecraft and anime all the way down

quote:

quote:

Today, his skillset for software development includes C#, Java, Golang, C, C++, PHP, x86 ASM, not to mention web ‘browser languages’ such as Javascript and HTML/CSS.”
[...]

After first reading Jha’s LinkedIn resume, I was haunted by the nagging feeling that I’d seen this rather unique combination of computer language skills somewhere else online. Then it dawned on me: The mix of programming skills that Jha listed in his LinkedIn profile is remarkably similar to the skills listed on Hackforums by none other than Mirai’s author — Anna-Senpai.

That's quite the jump. Surprised that was enough to make the whole connection go.

Malcolm XML
Aug 8, 2009

I always knew it would end like this.
so thats some serious circumstantial linking but did he inform the feds or what cause now ogmemes123123 (mods!!!!) is gonna try to wipe poo poo

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Wiggly Wayne DDS posted:

more eyepyramid info, it uses a lot more third-party software than previously thought: https://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-inner-workings-eyepyramid/

dang I'm slow. apparently I have one of the most recent samples! crrr.exe, but the table at https://documents.trendmicro.com/assets/Appendix_uncovering-the-inner-workings-of-eyepyramid.pdf doesn't include the c&c url (it's still https://webdav.hidrive.strato.com/users/oncole3991 btw, and don't bother going there as the account has been deactivated), and their "notable email addresses" column is misleading, it's really the usernames of the exfiltration webdav boxes, afaict

btw thanks spankmeister and/or whoever recommended de4dot because it was a godsend

I did eventually write the code to bruteforce the string encryption/anti-debugging protection hybrid algorithm, found some of the webdav boxes used for exfiltration, and wouldn't you know



one of those was still up! I'm terribly curious what's inside those files. I have to look up the exact encryption scheme used but the key and iv should simply be derived by hashing the filename

Luigi Thirty
Apr 30, 2006

Emergency confection port.

minecraft is serious business i guess

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

still handles vb code horribly. dotpeek works better for now, even when decompiling vb to c#

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
eyepyramid trivia: there's some unused code related to captchas, functions to download/upload both images and text from <url>/captcha/<unique id>. the same module contains code to scrape forms from the page currently open in IE and upload them. no idea about the captcha stuff but it seems out of place. I wonder if eyepyramid is part of a larger family of malware

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

BiohazrD posted:

eBay still lets you embed flash content into your listings apparently, so how about some auto downloading malware that makes it look like the official apple website



http://www.ebay.com/itm/350983607686?_trksid=p2060353.m2749.l2649&ssPageName=STRK%3AMEBIDX%3AIT

the shutoff date for active content in ebay listings is still over the course of may-june 2017, just like they announced at the beginning of last year

apseudonym
Feb 25, 2011


Play stupid games win stupid prizes

Wiggly Wayne DDS
Sep 11, 2010



hackbunny posted:

eyepyramid trivia: there's some unused code related to captchas, functions to download/upload both images and text from <url>/captcha/<unique id>. the same module contains code to scrape forms from the page currently open in IE and upload them. no idea about the captcha stuff but it seems out of place. I wonder if eyepyramid is part of a larger family of malware
from what i surmised the captcha section is a misdirect when communicating moderately sized blobs to weird domains

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Wiggly Wayne DDS posted:

from what i surmised the captcha section is a misdirect when communicating moderately sized blobs to weird domains

the code seems simply unused to me, and the "captcha" url component would go through the usual sha1 obfuscation anyway, so I'm not sure about this. and it really seems to be related to captchas, as it can for example deserialize received data to a System.Drawing.Image

unless you're talking about an older sample, I guess. crrr.exe/d3ad32bcb255e56cd2a768b3cbf6bafda88233288fc6650d0dfa3810be75f74c does nothing with it

A Man With A Plan
Mar 29, 2010
Fallen Rib

hackbunny posted:

dang I'm slow. apparently I have one of the most recent samples! crrr.exe, but the table at https://documents.trendmicro.com/assets/Appendix_uncovering-the-inner-workings-of-eyepyramid.pdf doesn't include the c&c url (it's still https://webdav.hidrive.strato.com/users/oncole3991 btw, and don't bother going there as the account has been deactivated), and their "notable email addresses" column is misleading, it's really the usernames of the exfiltration webdav boxes, afaict

btw thanks spankmeister and/or whoever recommended de4dot because it was a godsend

I did eventually write the code to bruteforce the string encryption/anti-debugging protection hybrid algorithm, found some of the webdav boxes used for exfiltration, and wouldn't you know



one of those was still up! I'm terribly curious what's inside those files. I have to look up the exact encryption scheme used but the key and iv should simply be derived by hashing the filename

While very cool, I'd recommend a lot of caution with putting any computer-linkable stuff related to you on a server that will almost certainly be part of a criminal investigation.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

A Man With A Plan posted:

While very cool, I'd recommend a lot of caution with putting any computer-linkable stuff related to you on a server that will almost certainly be part of a criminal investigation.

I took precautions. barring stupid mistakes I should be fine

Luigi Thirty
Apr 30, 2006

Emergency confection port.

hope you used log deleter v4 or they'll be able to trace you back to InterNIC and nuke your gateway

A Man With A Plan
Mar 29, 2010
Fallen Rib

hackbunny posted:

I took precautions. barring stupid mistakes I should be fine

Cool, just wanted to make sure. My secfuck of the day was some idiot sending possibly the worst phishing attempt I've ever seen to my entire alma mater. Looked like

code:
From: "Dr. University President" <studentname@otherUniversity.edu>
To : "Me" <me@myUniversity.edu>

Dear members of the university,

Please see my attached statement.
<president_statement.pdf>

Sincerely,
Dr. President
Office of the President
The person apparently used their own university email to send out the phishing emails. I wonder how lenient the courts will be.

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Luigi Thirty posted:

even my lovely Amiga browser from a million years ago can use a modern OpenSSL library port and TLS 1.2

the current version is 12.18 which came out last year with more modern SSL/TLS

spankmeister
Jun 15, 2008






A Man With A Plan posted:

Cool, just wanted to make sure. My secfuck of the day was some idiot sending possibly the worst phishing attempt I've ever seen to my entire alma mater. Looked like

code:
From: "Dr. University President" <studentname@otherUniversity.edu>
To : "Me" <me@myUniversity.edu>

Dear members of the university,

Please see my attached statement.
<president_statement.pdf>

Sincerely,
Dr. President
Office of the President
The person apparently used their own university email to send out the phishing emails. I wonder how lenient the courts will be.

Probably their account got hijacked because of easy to guess credentials. University email accounts are a popular target for spammers and scammers.

Shame Boy
Mar 2, 2010

Luigi Thirty posted:

minecraft is serious business i guess

oh my god minecraft drama is hilariously sad

there's mods that look for other mods that were made by the mod-maker's ~enemies~ and specifically nuke your game if they're installed

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/kaepora/status/821981816139747328

his lebanese passport was handwritten until early 2016

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER



Get ready to DDOS while invading oil nations boys.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i was going to make a joke about conscription coming to cyberwar but it's already a thing

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
only iot devices are conscripted to cyberwar, regular humans are still conscripted to regular war

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Boiled Water posted:



Get ready to DDOS while invading oil nations boys.

Would you like to know more?

Servers currently unavailable, please try again later.

spankmeister
Jun 15, 2008






OSI bean dip posted:

i was going to make a joke about conscription coming to cyberwar but it's already a thing

We already have "cyber reservists" here.

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

spankmeister posted:

We already have "cyber reservists" here.
I would guess a double-digit percentage of americans would install a DARPA-designed official LOIC-type app if the new administration advocated it. Or hell, just straight up pay telecoms to install servers in their networks, it's not like they've turned down free money for doing that in the past

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Bhodi posted:

I would guess a double-digit percentage of americans would install a DARPA-designed official LOIC-type app if the new administration advocated it. Or hell, just straight up pay telecoms to install servers in their networks, it's not like they've turned down free money for doing that in the past

that's insipid

NSA already installs stuff at telecom facilities

and the reason to use residental/small business internet connections for attacks is to make attribution difficult, hard to do when parties are going right out and saying "install this poo poo that lets us run attacks from your connection"

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Cocoa Crispies posted:

that's insipid

NSA already installs stuff at telecom facilities

and the reason to use residental/small business internet connections for attacks is to make attribution difficult, hard to do when parties are going right out and saying "install this poo poo that lets us run attacks from your connection"
serious question? does any one government department control enough resources to create a substantial ddos? I don't even know. I know there's a lot of server farms and some have taps everywhere, but what about actual traffic generation?

I'm not saying that it's necessarily smart or subtle, but as a ham-fisted way of putting pressure on someone I could kind of see the incoming administration looking at it as cyber gunboat diplomacy

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Bhodi posted:

serious question? does any one government department control enough resources to create a substantial ddos? I don't even know. I know there's a lot of server farms and some have taps everywhere, but what about actual traffic generation?

I'm not saying that it's necessarily smart or subtle, but as a ham-fisted way of putting pressure on someone I could kind of see the incoming administration looking at it as wizard gunboat diplomacy

seeing the goalposts on "substantial ddos" move in the last year or two, probably not, and that's okay, because no one man should have all that power, and the more minecrafters get behind bars i'm okay with that

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

OSI bean dip posted:

https://twitter.com/kaepora/status/821981816139747328

his lebanese passport was handwritten until early 2016

lol that was to sign up with n26

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

seeing the goalposts on "substantial ddos" move in the last year or two, probably not, and that's okay, because no one man should have all that power, and the more minecrafters get behind bars i'm okay with that

Supposedly the NSA's big bajillion dollar data center has a ton of bandwidth and a supercomputer attached so it probably could idk

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

ate all the Oreos posted:

Supposedly the NSA's big bajillion dollar data center has a ton of bandwidth and a supercomputer attached so it probably could idk

That'd all be coming off a few particular routes though, and thus be easy to block off.

Jewel
May 2, 2009

everyone's downloading "Meitu" today, the new craze hit which is a photo app that makes you look like an anime, there's tons of news articles about it and stuff already because of how fast it took off



sadly, uh, the permissions are Not Good



and it sends your IMEI data to china https://twitter.com/FourOctets/status/821987185188478977

aaaand more https://twitter.com/rekrom12/status/822134887226425344

Wiggly Wayne DDS
Sep 11, 2010



banime

Shame Boy
Mar 2, 2010

So it's your average analytics system that tries to get all your information to resell then

dragon enthusiast
Jan 1, 2010
owned by anime

30 TO 50 FERAL HOG
Mar 2, 2005



Jewel posted:

everyone's downloading "Meitu" today, the new craze hit which is a photo app that makes you look like an anime, there's tons of news articles about it and stuff already because of how fast it took off



sadly, uh, the permissions are Not Good



and it sends your IMEI data to china https://twitter.com/FourOctets/status/821987185188478977

aaaand more https://twitter.com/rekrom12/status/822134887226425344

anroid

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


it does the same poo poo on ios, zdziarski was going through it on twitter earlier

Adbot
ADBOT LOVES YOU

Salt Fish
Sep 11, 2003

Cybernetic Crumb

fishmech posted:

That'd all be coming off a few particular routes though, and thus be easy to block off.

With all that we know about NSA's hardware and software capabilities this is a super naive assumption. It's extremely likely that there are entire IoT botnets out there that have compromised control servers ready to be used by a variety of nation states. I would bet both of my testicles against a sandwich that at least 3 nation states have enough ddos capacity to take out the root nameservers.

  • Locked thread